vendor:
WM Downloader
by:
Blake
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: WM Downloader
Affected Version From: 3.0.0.9
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:wm_downloader:wm_downloader:3.0.0.9
Platforms Tested: Windows
2010
WM Downloader Buffer Overflow Exploit
This module exploits a stack overflow in WM Downloader version 3.0.0.9. By creating a specially crafted .pls file, an attacker may be able to execute arbitrary code.
Mitigation:
Apply the latest patch or upgrade to a non-vulnerable version of WM Downloader.